Notices
Site Suggestions & Problems Bring up any suggestions, questions or problems concerning ClubLexus. If you need to test a forum feature, post here too. Note - questions about your Lexus do not belong in this forum!

CL Site Malware thread (fixed, please let us know if you see issues)

Thread Tools
 
Search this Thread
 
Old Nov 4, 2012 | 02:57 PM
  #1  
Briano7's Avatar
Briano7
Thread Starter
Driver School Candidate
 
Joined: Sep 2012
Posts: 37
Likes: 0
From: FL
Default CL Site Malware thread (fixed, please let us know if you see issues)

I'm not sure where to post this but
Starting yesterday, the 3rd, when I sign on to Club Lexus Forum I get a popup warning from Norton Security saying:
Norton blocked an attack by:
EXPLOIT TOOLKIT
WEBSITE 33


Details:
Category: Intrusion Prevention
Date & Time,Risk,Activity,Status,Recommended Action,IPS Alert Name,Default Action,Action Taken,Attacking Computer,Attacker URL,Destination Address,Source Address,Traffic Description
2012-11-04 17:30:28,High,An intrusion attempt by dnsserv.ssrsystems.com was blocked.,Blocked,No Action Required,Web Attack: Exploit Toolkit Website 33,No Action Required,No Action Required,"dnsserv.ssrsystems.com (213.179.207.140, 80)",dnsserv.ssrsystems.com/dhFJwR?leETD=31,"OWNER-PC (192.168.1.68, 51765)",213.179.207.140 (213.179.207.140),"TCP, www-http"
Network traffic from <b>dnsserv.ssrsystems.com/dhFJwR?leETD=31</b> matches the signature of a known attack. The attack was resulted from \DEVICE\HARDDISKVOLUME1\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE. To stop being notified for this type of traffic, in the <b>Actions</b> panel, click <b>Stop Notifying Me</b>.

Just thought you ought to know.
It's supposed to be nasty.
Reply
Old Nov 4, 2012 | 06:16 PM
  #2  
YeA 2jZ's Avatar
YeA 2jZ
Lexus Fanatic
20 Year Member
Photogenic
Photoriffic
Shutterbug
iTrader: (15)
 
Joined: Apr 2005
Posts: 5,251
Likes: 3
From: SC Land, FL
Default Getting a Trojan warning in main SC Forum

When I reload the main & SC300/400 forum page I keep getting a "warning detected" "trojan" warning from my AVG. Its only been happening today ?

Last edited by YeA 2jZ; Nov 4, 2012 at 08:05 PM.
Reply
Old Nov 4, 2012 | 06:27 PM
  #3  
m1964's Avatar
m1964
Intermediate
 
Joined: Feb 2012
Posts: 280
Likes: 6
From: NY
Default any one else got the message?

While browsing this forum, I got a message from my antivirus program saying it blocked an attack on my computer-happened today, more then once on both work laptop and home desktop, with different anti-virus software....
Reply
Old Nov 4, 2012 | 06:59 PM
  #4  
YeA 2jZ's Avatar
YeA 2jZ
Lexus Fanatic
20 Year Member
Photogenic
Photoriffic
Shutterbug
iTrader: (15)
 
Joined: Apr 2005
Posts: 5,251
Likes: 3
From: SC Land, FL
Default

Reply
Old Nov 4, 2012 | 07:22 PM
  #5  
LexBob2's Avatar
LexBob2
Lexus Champion
15 Year Member
Liked
Loved
Community Favorite
 
Joined: Aug 2006
Posts: 12,492
Likes: 251
From: Illinois
Default

Originally Posted by m1964
While browsing this forum, I got a message from my antivirus program saying it blocked an attack on my computer-happened today, more then once on both work laptop and home desktop, with different anti-virus software....
I've been getting it regularly too.
Reply
Old Nov 4, 2012 | 07:43 PM
  #6  
RXSF's Avatar
RXSF
CL Community Team
15 Year Member
Photoriffic
Shutterbug
Community Builder
 
Joined: Aug 2006
Posts: 12,481
Likes: 198
From: San Francisco, CA
Default

Interesting. I am going to move or create a link to the site problems subforum so that Dave can be aware of the problem if he isnt already
Reply
Old Nov 4, 2012 | 07:46 PM
  #7  
GRPFAN's Avatar
GRPFAN
Pole Position
 
Joined: Nov 2011
Posts: 396
Likes: 1
From: Wisconsin
Default

Originally Posted by RXSF
Interesting. I am going to move or create a link to the site problems subforum so that Dave can be aware of the problem if he isnt already
I get a message that says" This site uses Java to view"
I ignore it and it's fine.
Reply
Old Nov 4, 2012 | 07:50 PM
  #8  
GRPFAN's Avatar
GRPFAN
Pole Position
 
Joined: Nov 2011
Posts: 396
Likes: 1
From: Wisconsin
Default

Originally Posted by YeA 2jZ
When I reload the main SC300/400 forum page I keep getting a "warning detected" "trojan" warning from my AVG. Its only been happening today ?
I'm atta here...
Reply
Old Nov 4, 2012 | 09:25 PM
  #9  
Supraman16's Avatar
Supraman16
Advanced
iTrader: (5)
 
Joined: Apr 2001
Posts: 587
Likes: 42
From: Burbank, CA
Default

I got infected from the FBI/Moneypak Malware virus this morning when I came to the clublexus forums. I managed to get rid of it by booting in Safe Mode and running MalwareBytes and then I got rid of Java to prevent it from getting into my computer. After that, I came back to ClubLexus and sure enough, you can tell there are some "data" (likely the virus again) that's trying to download into my computer. I think there is a virus tagged to clublexus.
Reply
Old Nov 4, 2012 | 09:50 PM
  #10  
DaveGS4's Avatar
DaveGS4
Administrator Emeritus
20 Year Member
Community Builder
Loved
Community Favorite
iTrader: (2)
 
Joined: Feb 2001
Posts: 31,944
Likes: 2,737
From: North Carolina
Default

Thanks all, I've sent this along to the tech folks. I'm sure any additional details you can provide (was it the same page each time?) will be helpful as are screen shots like yea posted (thanks)

Merged similar threads

Last edited by DaveGS4; Nov 4, 2012 at 09:54 PM.
Reply
Old Nov 5, 2012 | 03:18 AM
  #11  
Briano7's Avatar
Briano7
Thread Starter
Driver School Candidate
 
Joined: Sep 2012
Posts: 37
Likes: 0
From: FL
Default

I get the warning when I click the FORUMS button or the SPONSORS button.
Reply
Old Nov 5, 2012 | 04:43 AM
  #12  
TripleL's Avatar
TripleL
No Substitute
CL Folding 1,000,000
20 Year Member
Community Favorite
 
Joined: Nov 2005
Posts: 2,796
Likes: 51
From: RI
Default

Same here noticed it started Sunday night.

Posting what I recieved, hope it helps.

Code:
 
239	11/4/2012 8:01:48 PM	Intrusion Prevention	Critical	Incoming	TCP	213.179.207.140	80	N/A	64006	N/A	\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE	26033	69582	Web Attack: Exploit Toolkit Website 33	dnsserv.ssrsystems.com/dhFJwR?leETD=31		1	11/4/2012 8:01:35 PM	11/4/2012 8:01:35 PM	[SID: 26033] Web Attack: Exploit Toolkit Website 33 attack blocked. Traffic has been blocked for this application: \PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
240	11/4/2012 8:01:59 PM	Intrusion Prevention	Critical	Incoming	TCP	213.179.207.140	80	N/A	64167	N/A	\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE	26033	69582	Web Attack: Exploit Toolkit Website 33	dnsserv.ssrsystems.com/dhFJwR?leETD=31		1	11/4/2012 8:02:00 PM	11/4/2012 8:02:00 PM	[SID: 26033] Web Attack: Exploit Toolkit Website 33 attack blocked. Traffic has been blocked for this application: \PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
241	11/4/2012 8:03:39 PM	Intrusion Prevention	Critical	Incoming	TCP	213.179.207.140	80	N/A	64249	N/A	\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE	26033	69582	Web Attack: Exploit Toolkit Website 33	moloko.net-transfer.info/dhFJwR?leETD=31	1	11/4/2012 8:03:28 PM	11/4/2012 8:03:28 PM	[SID: 26033] Web Attack: Exploit Toolkit Website 33 attack blocked. Traffic has been blocked for this application: \PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
242	11/5/2012 7:26:15 AM	Intrusion Prevention	Critical	Incoming	TCP	213.179.207.140	80	N/A	49356	N/A	\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE	26033	69582	Web Attack: Exploit Toolkit Website 33	rokko.poundstone.co.uk/dhFJwR?leETD=31		2	11/5/2012 7:25:02 AM	11/5/2012 7:25:12 AM	[SID: 26033] Web Attack: Exploit Toolkit Website 33 attack blocked. Traffic has been blocked for this application: \PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
243	11/5/2012 7:28:40 AM	Intrusion Prevention	Critical	Incoming	TCP	213.179.207.140	80	N/A	49395	N/A	\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE	26033	69582	Web Attack: Exploit Toolkit Website 33	rokko.poundstone.co.uk/dhFJwR?leETD=31		1	11/5/2012 7:27:37 AM	11/5/2012 7:27:37 AM	[SID: 26033] Web Attack: Exploit Toolkit Website 33 attack blocked. Traffic has been blocked for this application: \PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
244	11/5/2012 7:34:54 AM	Intrusion Prevention	Critical	Incoming	TCP	213.179.207.140	80	N/A	49500	N/A	\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE	26033	69582	Web Attack: Exploit Toolkit Website 33	rokko.poundstone.co.uk/dhFJwR?leETD=31		1	11/5/2012 7:33:53 AM	11/5/2012 7:33:53 AM	[SID: 26033] Web Attack: Exploit Toolkit Website 33 attack blocked. Traffic has been blocked for this application: \PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Attached Thumbnails CL Site Malware thread (fixed, please let us know if you see issues)-cl-concern.jpg  

Last edited by TripleL; Nov 5, 2012 at 05:04 AM.
Reply
Old Nov 5, 2012 | 06:24 AM
  #13  
Robb M.'s Avatar
Robb M.
Internet Brands
15 Year Member
 
Joined: Mar 2010
Posts: 58
Likes: 106
From: ON
Default

Are you all using IE?
Reply
Old Nov 5, 2012 | 07:26 AM
  #14  
neurocity's Avatar
neurocity
Not quite my tempo
20 Year Member
iTrader: (17)
 
Joined: Jan 2006
Posts: 9,941
Likes: 776
From: Chicago
Default

I just got nailed, on iPad now while I run Malwarebytes to clean in safe mode.

Wtf!? I never get hit with stuff, first time in like ten years, on my work laptop no less. This was fast as hell too... Like I just clicked on the main forum page and then this just popped up. I can only imagine what's nailing everyone else.

Windows seven 64bit, Mozilla latest release. Norton.
Reply
Old Nov 5, 2012 | 08:27 AM
  #15  
Lil4X's Avatar
Lil4X
Out of Warranty
20 Year Member
Photogenic
Photoriffic
Shutterbug
 
Joined: Aug 2001
Posts: 14,925
Likes: 13
From: Houston, Republic of Texas
Default

Got the same Norton flags yesterday and today, CL has become unstable. I'm shutting down to run Malwarebytes too.


W/7, Firefox, Norton, on Comcast
Reply



All times are GMT -7. The time now is 11:48 PM.